North Korean Hackers Launder $300M from $1.5B ByBit Crypto Heist

North Korean hackers, believed to be part of the notorious Lazarus Group, have successfully laundered at least $300 million from their record-breaking $1.5 billion cryptocurrency heist. The cybercriminals stole the funds in a hack targeting crypto exchange ByBit two weeks ago and have been working tirelessly to convert the stolen digital tokens into usable cash.

A Race Against Time to Track Stolen Funds

Since the hack, cybersecurity experts have been tracking the movement of the stolen funds, attempting to prevent the hackers from cashing out. However, investigators say the Lazarus Group operates with an extreme level of sophistication.

“Every minute matters for the hackers who are trying to obscure the money trail, and they are extremely skilled at it,” said Dr. Tom Robinson, co-founder of crypto security firm Elliptic.

According to Dr. Robinson, North Korean hackers are the most advanced criminal group when it comes to laundering cryptocurrency. He believes they have a dedicated team working in shifts, using automated tools to move the funds and evade detection.

How the Hack Happened

On February 21, the hackers infiltrated one of ByBit’s suppliers and secretly altered the digital wallet address used for transactions. As a result, when ByBit transferred 401,000 Ethereum coins, worth $1.5 billion, the funds were sent directly to the hackers instead of the company’s own digital wallet.

ByBit’s CEO, Ben Zhou, has assured customers that their funds were not affected. The company has since replenished the lost amount through investor loans and has vowed to track down the hackers. Zhou stated that ByBit is “waging war on Lazarus” and has launched a bounty program to encourage the public to help trace the stolen funds.

Efforts to Recover the Stolen Crypto

All cryptocurrency transactions are recorded on public blockchains, allowing investigators to follow the stolen funds. If the hackers attempt to convert the stolen crypto into traditional currency using mainstream exchanges, the transactions can be flagged and blocked.

ByBit’s bounty program has already paid over $4 million in rewards to individuals who helped identify and freeze approximately $40 million of stolen funds. However, experts are doubtful that the remaining funds can be recovered, given North Korea’s advanced laundering tactics.

Dr. Dorit Dor, a cybersecurity expert at Check Point, said North Korea has built a highly effective system for cyber theft and laundering. “They don’t care about the negative reputation that comes with cybercrime. They have turned hacking into a state-run industry.”

Controversy Over Crypto Exchange eXch

Efforts to block the stolen funds have been hindered by some cryptocurrency exchanges. ByBit has accused eXch, a crypto trading platform, of allowing more than $90 million of the stolen funds to be cashed out.

The owner of eXch, Johann Roberts, admitted that his platform did not initially block the stolen funds due to an ongoing dispute with ByBit. However, he later claimed to be cooperating with efforts to track and freeze the transactions.

Roberts also criticized mainstream crypto companies for identifying users, arguing that it goes against the core principle of cryptocurrency—anonymity.

North Korea’s Growing Crypto Crime Network

North Korea has never admitted to being behind the Lazarus Group, but it is widely believed to be the only country using cybercrime to fund state operations. The country’s hackers have shifted from targeting banks to focusing on crypto exchanges, which have weaker security measures.

Some of the major cryptocurrency heists linked to North Korea include:

2019: UpBit exchange hacked for $41 million

2020: KuCoin targeted, leading to a $275 million theft (most funds were recovered)

2022: Ronin Bridge attack, where $600 million was stolen

2023: Atomic Wallet hack resulting in a $100 million loss

In 2020, the U.S. placed North Korean hackers associated with the Lazarus Group on its Cyber Most Wanted list. However, given North Korea’s isolation, the chances of these individuals being arrested remain low unless they travel outside the country.

With the Lazarus Group continuing to refine its tactics, experts warn that crypto exchanges must strengthen security measures to prevent future attacks.

Technology

Meta Expands Teen Safety Features to Facebook and Messenger
Meta Expands Teen Safety Features to Facebook and Messenger

Meta is rolling out its Teen Accounts safety system to Facebook and Messenger, aiming to create a more secure experience for users under 18.

BYD Unveils Sealion SUVs and Shark Bakkie in South Africa
BYD Unveils Sealion SUVs and Shark Bakkie in South Africa

Chinese automaker BYD has launched its new range of vehicles in South Africa, featuring the Sealion SUVs and the Shark bakkie.

ChatGPT’s New AI Image Generator Now Available for Free Users
ChatGPT’s New AI Image Generator Now Available for Free Users

OpenAI has announced that its latest AI image generator, "Images in ChatGPT," is now accessible to free users.

Garmin Introduces AI and Subscription Plan for Premium Features
Garmin Introduces AI and Subscription Plan for Premium Features

Garmin has announced a new premium subscription service, Garmin Connect Plus, which introduces AI-powered insights and additional features for users.

EFCC, Army Arrest 133 in Abuja Over Ponzi Scheme Academy
EFCC, Army Arrest 133 in Abuja Over Ponzi Scheme Academy

Nigerian authorities have arrested 133 suspects linked to a Ponzi scheme academy that promised unrealistic financial gains.

Tesla Dealerships Targeted as Musk Condemns “Evil Attacks”
Tesla Dealerships Targeted as Musk Condemns “Evil Attacks”

Attacks on Tesla dealerships, charging stations, and vehicles have been increasing across the U.S. and overseas, with vandals targeting the electric car company owned by Elon Musk.

Singapore’s AI Chip Fraud Case Sparks Global Trade Concerns
Singapore’s AI Chip Fraud Case Sparks Global Trade Concerns

Singapore is at the center of a major fraud case involving the alleged illegal export of AI-capable servers, some possibly containing Nvidia chips, to Malaysia.

Google to Buy Cloud Security Firm Wiz for $32 Billion
Google to Buy Cloud Security Firm Wiz for $32 Billion

Google has announced plans to acquire Wiz, a cloud security platform, in an all-cash deal worth $32 billion.

WhatsApp Now Lets Users Add Music to Status Updates
WhatsApp Now Lets Users Add Music to Status Updates

WhatsApp has introduced a new feature that allows users to add music to their status updates, making it easier to share their mood, favorite songs, or lyrics with friends and family.

Other Stories
NASA Astronauts Finally Return After Nine Months Stranded in Space
NASA Astronauts Finally Return After Nine Months Stranded in Space

NASA astronauts Butch Wilmore and Suni Williams are finally heading back to Earth after spending more than nine months in space due to delays caused by a failed Boeing test flight.

Google’s AI Model Can Remove Watermarks, Raising Copyright Concerns
Google’s AI Model Can Remove Watermarks, Raising Copyright Concerns

Google’s new AI model, Gemini 2.0 Flash, has sparked controversy after social media users discovered it can remove watermarks from images with remarkable accuracy.

Crew 10 Arrives at ISS, Replacing Astronauts After 290 Days in Space
Crew 10 Arrives at ISS, Replacing Astronauts After 290 Days in Space

A SpaceX Crew Dragon capsule docked with the International Space Station (ISS) early Sunday, delivering four new astronauts and clearing the way for two long-stranded Starliner astronauts to finally return home after nearly 300 days in space.


NASA, SpaceX Launch Crew to Replace Starliner Astronauts in Space
NASA, SpaceX Launch Crew to Replace Starliner Astronauts in Space

After multiple delays, a SpaceX rocket carrying four astronauts successfully launched on Friday, heading toward the International Space Station (ISS).

SpaceX Delays NASA Astronaut Rescue Mission Over Launch Pad Issue
SpaceX Delays NASA Astronaut Rescue Mission Over Launch Pad Issue

SpaceX has postponed a crucial flight intended to replace NASA astronauts stranded on the International Space Station (ISS) due to a technical issue at the launch pad.

TECNO CAMON 40 Launches With AI-Powered Photography Features
TECNO CAMON 40 Launches With AI-Powered Photography Features

Smartphone photography has taken a major leap forward with the launch of the TECNO CAMON 40 Series, bringing speed, intelligence, and precision together for an exceptional photography experience.